---
id: CVE-2020-29230
title: >-
  EGavilanMedia User Registration and Login System With Admin Panel 1.0 is
  affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab
  using the Full Name of the user
summary: >-
  EGavilanMedia User Registration and Login System With Admin Panel 1.0 is
  affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab
  using the Full Name of the user. This vulnerability can result in the attacker
  injecting…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: egavilanmedia
product: user_registration_and_login_system_with_admin_panel
affected:
  - user_registration_and_login_system_with_admin_panel = 1.0
published: '2020-12-30'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-29230'
references:
  - url: 'https://github.com/hemantsolo/CVE-Reference/blob/main/CVE-2020-29230.md'
    label: cve@mitre.org
  - url: 'http://egavilanmedia.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/hemantsolo/CVE-Reference/blob/main/CVE-2020-29230.md'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00807
epssPercentile: 0.55002
ingestedAt: '2026-07-05T00:59:25.598Z'
---

## Overview

EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerability can result in the attacker injecting the XSS payload in the User Registration section and each time admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal the cookie according to the crafted payload.

## Affected

- `user_registration_and_login_system_with_admin_panel = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
